ISO management systems consulting — six standards, one integrated system
Six standards, all held at Lead Auditor level by our founder, implemented as one integrated management system wherever your scope allows it. Documentation is written from your actual processes, and the evidence trail is built with it.
Six ISO standards, at Lead Auditor level
ISO/IEC 27001:2022
Information security management. The backbone system, and the most efficient route to demonstrating the NIS2 Article 21 measures.
Explore →ISO/IEC 27701:2025
Privacy information management — now a standalone, certifiable standard. The practical way to evidence GDPR and KVKK accountability.
Explore →ISO 22301:2019
Business continuity. Business impact analysis, recovery strategies, exercises — and the evidence base for NIS2 Article 21(2)(c).
Explore →ISO/IEC 20000-1:2018
IT service management. Service catalogue, SLA and KPI design, incident, problem and change management, alongside ITIL practice design.
Explore →ISO/IEC 42001:2023
AI management systems. Governance, impact assessment and lifecycle controls for organisations developing or deploying AI.
Explore →ISO 9001
Quality management, integrated with the others under one audit programme and one management review. Revision ISO 9001:2026 at publication stage.
Explore →Three systems, three document sets, three audit cycles that contradict each other
Organisations frequently arrive with exactly that. We consolidate: one context and scope, one risk method, one document control system, one internal audit programme, one management review — with standard-specific annexes. Less documentation, fewer audit days, fewer findings.
One risk method
Information security, continuity and privacy risks in the same methodology and the same register, repeatable every year.
One audit programme
A combined internal audit plan, shared evidence, a single finding register and single reporting.
One management review
Top management reviews every system in one meeting, with one decision record.
Implementation in nine steps
We do not treat certification as the finish line. The system has to survive the surveillance audit two years later without us.
Gap analysis
Current practice assessed against the standard’s requirements and controls, scored, with a prioritised remediation list.
Context, scope and risk method
Interested parties, boundaries, and a risk methodology the organisation can actually repeat annually.
Risk assessment and treatment
Threats, vulnerabilities and impacts identified and prioritised; treatment plan agreed with management.
Documentation development
Policies, procedures and records written to your processes, not imported from a template library.
Implementation and integration
Requirements embedded into live business processes, with the operational teams who will run them.
Awareness and competence
Role-based training so the people named in the documents know what they are responsible for.
Internal audit and management review
A full cycle completed before the external audit, with corrective actions closed.
Certification support
Certification body selection, Stage 1 and Stage 2 attendance, finding response and closure.
Continual improvement
Surveillance audit preparation and periodic review so the system does not decay between cycles.
Frameworks as implementation vehicles
Management system standards say what must be managed. Frameworks say what to deploy, and in what order. We use them underneath the ISO programme, not as slideware:
- NIST CSF 2.0 — six functions including the new Govern function; maturity assessment and roadmap design, mapped to ISO/IEC 27001 and NIS2 Article 21
- CIS Controls v8.1 — 18 prioritised controls in implementation groups IG1–IG3; the practical delivery engine for technical measures
- ITIL 4 and ITIL (Version 5), released in stages during 2026 — practice design behind ISO/IEC 20000-1
Engagement summary
- ISO/IEC 27001 duration
- Typically 4–9 months, depending on scope and maturity
- Delivered as
- Word and Excel; version-controlled, metadata cleaned, document IDs applied
- Language
- English by default for EU clients; Turkish available
- Certificate
- Issued by the accredited certification body you select
Where the management system meets the law
About ISO management systems
Does it make sense to implement several standards at once?
Where your scope allows it, yes. We build one context and scope, one risk method, one document control system, one internal audit programme and one management review, and keep the standard-specific requirements in annexes. The result is less documentation, fewer audit days and fewer findings.
Which standard should we start with?
For most organisations the backbone is ISO/IEC 27001: it answers NIS2 Article 21, GDPR security of processing and most customer security questionnaires with one system. Personal-data-heavy business models may put ISO/IEC 27701 first, and operations with low tolerance for disruption ISO 22301. We agree the sequence with you in the scoping call.
Does Infosec Academy issue the certificate?
No. Certificates are issued by accredited certification bodies, which under ISO/IEC 17021-1 may not provide consultancy. We implement the system, train your people, run the internal audit, and support you through the Stage 1 and Stage 2 audits by the certification body you select.
In which language are the documents produced?
English by default for EU clients and EU group companies, Turkish where the system operates in Türkiye. Every deliverable is version-controlled, metadata-cleaned and carries a document ID.
Let us start with a scoping conversation
Thirty to forty-five minutes is usually enough to establish scope, a realistic timeline, and whether we are the right people for the work.